Radiology Departments at Higher Risk for Ransomware Attacks
On July 16, 2026, the CHAOS ransomware group posted a claim on Tor alleging it had compromised Radia Inc., P.S., one of the largest physician-owned radiology groups in the United States, serving over 50 clinics across Washington and Idaho [3][4]. The group claimed to have exfiltrated 655 gigabytes of data spanning patient records, corporate financials, legal documents, and employee information [3]. As of August 1, 2026, Radia had not confirmed the breach or filed reports with state attorneys general [4]. A class-action investigation is already underway [4].
This is not an isolated event. In the same reporting period, Women's Center for Radiology in Orlando, Florida, notified patients of unauthorized network access discovered around April 28, 2026 [2]. Northwest Radiologists and Mount Baker Imaging in Bellingham, Washington, agreed to a $3.3 million settlement consolidating four lawsuits from a January 2025 ransomware attack that exposed data belonging to an estimated 350,000 patients [1]. According to BlackFog, healthcare was among the most heavily targeted sectors for publicly disclosed ransomware attacks in July 2026 [2].
Healthcare Ransomware Activity: The Current State
The FBI reported that healthcare organizations were the most targeted critical infrastructure sector for ransomware in 2025 [7][16]. In the European Union, ENISA documented at least 289 cybersecurity incidents affecting healthcare providers in 2024, more than any other essential sector, and ransomware was responsible for an estimated 71% of those incidents that disrupted patient care [16].
Sophos surveyed healthcare IT and cybersecurity leaders and found notable tactical shifts. Data encryption in healthcare ransomware incidents fell to 34% in 2025 from 74% in 2024, a five-year low[14][15]. Extortion-only attacks (data stolen but not encrypted) tripled to 12% of healthcare cases[14]. Only 36% of healthcare providers paid a ransom, down from 61% in 2022[15]. According to reporting on the Sophos survey, median ransom demands dropped significantly to roughly $345,000 [15]. Recovery times improved: 58% of healthcare organizations recovered within a week, up from 21% reported in 2024[15].
These figures suggest healthcare organizations are getting better at resisting encryption and refusing payment. Ransomware operators are adapting accordingly, pivoting toward pure data extortion. The sensitivity of medical records, including imaging data, makes this model viable even without deploying an encryptor.
Why Radiology Departments Carry Concentrated Risk
Po-Hao Chen, MD, security committee chair of the Society for Imaging Informatics in Medicine (SIIM), stated at the SIIM 2026 annual meeting that attacks on hospital radiology departments have increased exponentially since 2000, a timeline that correlates with the shift to all-digital radiology operations [7]. No published data exists on successful attacks against hospital radiology departments specifically, Chen noted, but available data suggests an upward trend [7].
Three structural factors explain the concentration of risk.
Data density. Radiology practices generate and store terabytes of imaging data linked to protected health information. The CHAOS group's claim against Radia Inc. illustrates the scope: 655 gigabytes allegedly containing patient full names, Social Security numbers, medical record numbers, diagnostic imaging reports, patient history questionnaires, and full medical billing records [3]. Corporate financials, legal documents, and HR records were also claimed [3].
Device and system sprawl. Modern radiology depends on a highly connected digital ecosystem. Data moves continuously between electronic health records, radiology information systems, PACS platforms, scanners, AI inference engines, workstations, reporting tools, and third-party cloud applications [7][16]. Each integration point is a potential entry vector. Clinical imaging systems can legitimately produce file-operation bursts, complicating detection of ransomware behavior [20].
Legacy infrastructure and staffing gaps. CT and MRI scanners frequently run embedded operating systems that vendors no longer patch. US Radiology Specialists paid $450,000 in penalties to New York State after an investigation found the company had not prioritized upgrading hardware, leaving its network exposed to a known vulnerability that enabled a ransomware attack affecting over 92,000 New Yorkers [17]. Sophos found that 42% of healthcare ransomware victims cited lack of personnel or capacity as the top organizational cause of their breach[14].
CHAOS
CHAOS is a Ransomware-as-a-Service group first observed in early 2025, distinct from the older Chaos Ransomware Builder that originated around 2021 [6]. The group targets organizations across Windows, ESXi, Linux, and NAS platforms using double-extortion tactics with configurable encryption and optional partial-file targeting for stealth [6]. Initial access comes through vulnerabilities, phishing, or brokered credentials [6]. Beyond the Radia Inc. claim, notable CHAOS incidents include the breach of Optima Tax Relief, where the group exfiltrated 69 GB of data before encrypting systems [6].
Medusa
CISA, the FBI, and HHS have issued a joint advisory on Medusa ransomware (AA25-071A). The advisory documents more than 300 compromised organizations across critical infrastructure sectors as of February 2025, and according to secondary reporting, the advisory was updated in August 2026 to reflect more than 500 victims[13]. Medusa, a RaaS variant first identified in June 2021, uses a double-extortion model combining encryption with threatened data publication. Impacted sectors include medical, education, legal, insurance, technology, and manufacturing.
Gunra
CISA, FBI, and partner agencies released a joint #StopRansomware advisory on Gunra, a RaaS variant reported to be derived from leaked Conti source code. Gunra actors gain initial access by exploiting CVE-2024-55591 and CVE-2025-24472 in internet-facing Fortinet FortiOS and FortiProxy devices. Targeted sectors include healthcare and public health, financial services, government, and professional services.
Qilin
Qilin (originally Agenda) has been active since at least 2022, operating as a RaaS with variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments [10]. The group shares functionality overlaps with Black Basta, REvil, and BlackCat [10]. The June 2024 attack on Synnovis, an NHS pathology services provider, reportedly halted approximately 90% of blood testing capacity and forced over 1,100 surgeries and 2,000 outpatient appointments to be canceled within two weeks [9]. Qilin affiliates use spearphishing, exploitation of public-facing applications (Citrix, RDP, VPNs), and compromised credentials from infostealer malware for initial access [11].
Operational Impact on Imaging Departments
A Dutch-led international study presented at the European Congress of Radiology (ECR) 2026 found that ransomware attacks significantly affect emergency radiology workflow, acute care delivery, and staff well-being.
During the 2021 Irish Health Service Executive ransomware attack, decryption took a week to begin. Junior radiologists were sent to consumer electronics stores to buy external hard drives. Departments reverted to carbon paper and handwritten triplicate reports. A hospital near Paris experienced a ransomware attack that continued to severely impact all departments' IT systems and web access, with imaging particularly affected.
The Boston Scientific incident in August 2026, detected on August 25 and disclosed via SEC Form 8-K on August 26, caused a widespread network outage that halted global customer order processing and distribution [18]. According to reporting by ShieldWorkz, BSX stock fell approximately 3.5% in premarket trading [18]. No threat actor had publicly claimed responsibility as of August 31, 2026 [18]. According to ShieldWorkz analysis, the attack pattern appears consistent with a double-extortion ransomware intrusion [18]. Although Boston Scientific is a medical device manufacturer rather than a radiology practice, downstream supply chain disruption to hospitals relying on just-in-time deliveries of critical devices is a direct operational concern [18].
IOC Table
| Type | Value | Context | Source |
|---|---|---|---|
| Malware | CHAOS | RaaS group, claimed Radia Inc. breach, July 2026 | [3][4][6] |
| Malware | Medusa | RaaS, 300-500+ victims, healthcare focus, CISA advisory AA25-071A | [13] |
| Malware | Gunra | RaaS, CISA advisory Aug 2026 | |
| Malware | Qilin | RaaS active since 2022, NHS Synnovis attack | [9][10] |
| CVE | CVE-2024-55591 | Fortinet FortiOS/FortiProxy authentication bypass, CVSS 9.8, exploited by Gunra | |
| CVE | CVE-2025-24472 | Fortinet FortiOS/FortiProxy CSF proxy authentication bypass, exploited by Gunra |
MITRE ATT&CK Mapping
The following techniques are directly supported by the source material for the threat groups discussed:
| ID | Technique | Relevance |
|---|---|---|
| T1566.001 | Phishing: Spearphishing Attachment | Medusa, Qilin, CHAOS initial access [6][11] |
| T1566.002 | Phishing: Spearphishing Link | Medusa phishing for credential theft |
| T1190 | Exploit Public-Facing Application | Gunra (CVE-2024-55591, CVE-2025-24472); Qilin (Citrix, VPN) [11] |
| T1078 | Valid Accounts | Brokered/stolen credentials for initial access [6][11] |
| T1059.001 | PowerShell | Medusa obfuscation techniques; healthcare intrusion chains [21] |
| T1059.003 | Windows Command Shell | Living-off-the-land execution [21] |
| T1021.001 | Remote Services: RDP | Lateral movement in healthcare networks [11][21] |
| T1486 | Data Encrypted for Impact | Core ransomware function across all groups [6][9] |
| T1490 | Inhibit System Recovery | Shadow copy deletion prior to encryption [9] |
| T1567.002 | Exfiltration Over Web Service: Exfiltration to Cloud Storage | Double-extortion data theft [3] |
| T1548.002 | Abuse Elevation Control Mechanism: Bypass UAC | Qilin privilege escalation [10] |
| T1003.001 | OS Credential Dumping: LSASS Memory | Credential harvesting during lateral movement [10] |
| T1489 | Service Stop | Stopping security and backup services pre-encryption [9] |
Detection and Hunting
Ransom note file creation. Monitor for creation of files matching known ransom note patterns. The following Sigma rule targets common naming conventions:
title: Ransom Note File Creation in Healthcare Environment
status: experimental
author: RedSheepSec
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|contains:
- 'HOW_TO_DECRYPT'
- 'RECOVER_FILES'
- 'RESTORE_YOUR_FILES'
- 'DECRYPT_INSTRUCTION'
- 'README_FOR_DECRYPT'
condition: selection
level: critical
PsExec and living-off-the-land lateral movement. Ransomware operators in healthcare consistently use PsExec, WMI, PowerShell, and RDP for lateral movement rather than custom malware [21]. Hunt for PsExec execution from non-standard paths, WMI process creation spawning cmd.exe or powershell.exe on remote hosts, and RDP sessions originating from unexpected internal sources.
PACS and imaging system baselines. Clinical imaging systems legitimately produce file-operation bursts that can trigger false positives for mass file-rename detection rules [20]. Establish baselines for normal DICOM file I/O patterns on PACS servers and set alert thresholds above those baselines.
Unpatched internet-facing appliances. Gunra's documented initial access vector exploits CVE-2024-55591 and CVE-2025-24472 in Fortinet FortiOS and FortiProxy devices. Exploited vulnerabilities were the top technical cause of healthcare ransomware in 2025, accounting for 33% of incidents[14]. Scan for these CVEs and prioritize patching VPN concentrators, firewalls, and remote access gateways.
Extortion-only detection. With encryption rates falling and extortion-only attacks tripling[14], organizations that focus detection exclusively on encryption events will miss a growing share of intrusions. Monitor for bulk file access, staging of archive files (ZIP, 7z, RAR) in unusual directories, and large outbound data transfers to uncommon destinations.
Analysis
The ransomware threat to radiology is not diminishing. It is shifting form. The drop in encryption rates and ransom payments reported by Sophos[14][15] does not mean healthcare organizations are safe. It means attackers have learned that stealing radiology data, with its dense mix of PII, PHI, and imaging records, can generate sufficient extortion pressure without the operational noise of deploying an encryptor.
The CHAOS claim against Radia Inc. is a case study in this model. The group published a sample of stolen data and threatened to release the rest unless negotiations proceeded [5]. The claimed dataset (655 GB) spans patient records, billing, legal documents, and HR files [3]. For a radiology group serving 50+ clinics, a verified breach of that scope would trigger HIPAA notification obligations, state attorney general investigations, and class-action litigation, as the Northwest Radiologists settlement demonstrates [1][4].
The joint ACR/SIIM cybersecurity guidelines published in 2025 represent the first comprehensive, imaging-specific security framework from the profession's own leadership [7][8]. The guidelines address the imaging pipeline, frontline caregiver training, and incident response planning [8]. Their publication signals recognition within radiology that the profession's digital dependency has outpaced its security posture.
The August 2026 Boston Scientific incident adds a supply-chain dimension [18]. Hospitals relying on just-in-time delivery of implantable devices face downstream disruption when a manufacturer's order processing and distribution systems go offline. Radiology departments that depend on vendor-managed equipment, cloud-hosted AI inference, or third-party PACS hosting carry analogous supply-chain exposure.
Red Sheep Assessment
Confidence: Moderate
The sources collectively point to a structural mismatch between the value of radiology data and the security resources available to protect it. Radiology practices, particularly physician-owned groups and outpatient imaging centers, operate with thin IT staffing and legacy device inventories. They generate and store data that is among the most valuable in healthcare for extortion purposes: dense PII/PHI, diagnostic imaging, and billing records.
We assess that the shift toward extortion-only attacks is likely to accelerate targeting of radiology specifically. An attacker who can exfiltrate a radiology group's data without encrypting anything avoids the operational disruption that triggers rapid incident response. The breach may not be discovered until the extortion demand arrives or data appears on a leak site. Radia Inc. had not confirmed its breach or filed regulatory notifications as of August 1, 2026, despite the CHAOS group's July 16 posting [4].
A contrarian reading is that the Sophos data showing declining ransom payments and faster recovery could indicate the healthcare sector is genuinely hardening. The ACR/SIIM guidelines, the CISA CI Fortify initiative [19], and the updated Medusa and Gunra advisories represent coordinated defensive momentum. The question is whether that momentum reaches the small and mid-sized radiology practices that lack enterprise security teams. According to secondary reporting, Medusa's victim profile skews toward organizations that lack enterprise security teams [13]. The same is likely true for many radiology groups.
Defender's Checklist
- ▢[ ] Audit all internet-facing Fortinet FortiOS and FortiProxy appliances for CVE-2024-55591 (CVSS 9.8) and CVE-2025-24472. Apply FortiOS patches per Fortinet PSIRT advisory FG-IR-24-535. Gunra actively exploits both.
- ▢[ ] Implement monitoring for bulk file access and large outbound transfers from PACS servers, RIS, and EHR-connected imaging shares. Extortion-only attacks will not trigger encryption-based alerts[14][20].
- ▢[ ] Review and apply the ACR/SIIM joint cybersecurity white paper (2025, DOI: 10.1007/s10278-025-01621-4) for imaging-specific hardening, incident response, and vendor management guidance [7][8].
- ▢[ ] Enforce phishing-resistant MFA (FIDO2/WebAuthn) on all VPN and remote access accounts. Confirm backup integrity and test offline restoration procedures for PACS and RIS systems[15].
- ▢[ ] Baseline normal file I/O patterns on PACS servers and DICOM storage to establish reliable detection thresholds for mass file-rename or mass file-access anomalies [20].
References
[1] https://radiologybusiness.com/topics/healthcare-management/legal-news/radiology-practice-agrees-3m-settlement-class-action-lawsuit-over-cyberattack
[2] https://www.blackfog.com/the-state-of-ransomware-2026/
[3] https://www.claimdepot.com/data-breach/radia-2026
[4] https://www.classactionlawyers.com/blog/radia
[5] https://www.dexpose.io/chaos-ransomware-group-strikes-radia-inc/
[6] https://www.ransomlook.io/group/chaos
[7] https://healthcare-in-europe.com/en/news/radiology-ransomware-cyberattack.html
[8] https://link.springer.com/article/10.1007/s10278-025-01621-4
[9] https://www.blackfog.com/qilin-ransomware-analysis-impact-and-defense-2025/
[10] https://attack.mitre.org/software/S1242/
[11] https://www.rescana.com/post/qilin-ransomware-attack-analysis-technical-assessment-of-q-link-wireless-incident-and-sector-specific-mitigation-strateg
[12] https://blog.qualys.com/vulnerabilities-threat-research/2025/06/18/qilin-ransomware-explained-threats-risks-defenses
[13] https://www.cyberfenceplatform.com/blog/medusa-ransomware-2026
[14] https://hitconsultant.net/2025/11/21/ransomware-state-of-healthcare-2025/
[15] https://cxotoday.com/media-coverage/sophoss-state-of-ransomware-in-healthcare-2025-report-reveals-58-of-providers-now-recover-within-a-week-amid-declining-ransom-payments-across-the-sector/
[16] https://quomi.com/radiology/radiology-vs-ransomware-how-to-defend-imaging-departments-against-cyberattacks
[17] https://ag.ny.gov/press-release/2023/attorney-general-james-secures-450000-medical-company-providing-services-western
[18] https://shieldworkz.com/blogs/deep-dive-into-the-boston-scientific-cyberattack
[19] https://www.paubox.com/blog/cisa-warns-healthcare-should-prepare-for-disruptive-cyberattacks
[20] https://securityarsenal.com/blog/ransomware-breaches-at-five-us-healthcare-providers-detection-and-hardening-guide-for-defenders
[21] https://cybelangel.com/blog/ransomware-in-healthcare-attack-timeline/
Visual Intelligence
Timeline (6 events)
Entity Graph (17 entities, 38 relationships)
Diamond Model
---
Hunt Guide: Healthcare Radiology Ransomware Campaign - CHAOS, Medusa, Gunra, and Qilin RaaS Groups
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If CHAOS, Medusa, Gunra, or Qilin ransomware operators are active in our environment, we expect to observe exploitation of Fortinet FortiOS vulnerabilities (CVE-2024-55591, CVE-2025-24472) on internet-facing appliances, spearphishing-driven initial access, lateral movement via PsExec/RDP/WMI/PowerShell, credential dumping from LSASS, bulk file access and staging of archive files on imaging and PACS-adjacent systems, large outbound data transfers to uncommon cloud destinations, shadow copy deletion, and ransom note file creation across Windows endpoints, network telemetry, and firewall logs.
Intelligence Summary: Multiple ransomware-as-a-service groups, including CHAOS, Medusa, Gunra, and Qilin, are actively targeting healthcare organizations with a pronounced focus on radiology departments due to their high data density, device sprawl, and legacy infrastructure. The CHAOS group claimed a 655 GB exfiltration from Radia Inc. in July 2026, and the broader trend shows a tactical shift toward extortion-only attacks (data theft without encryption), which tripled to 12% of healthcare cases according to Sophos reporting. Gunra actors specifically exploit CVE-2024-55591 and CVE-2025-24472 in Fortinet FortiOS and FortiProxy devices for initial access, while Medusa has compromised over 500 organizations across critical infrastructure as documented in updated CISA advisory AA25-071A.
Confidence: Moderate | Priority: Critical
Scope
- Networks: All healthcare networks with radiology, PACS, RIS, and imaging infrastructure. Include segments hosting DICOM storage, imaging workstations, AI inference engines, and third-party cloud-connected imaging applications. Include internet-facing Fortinet FortiOS and FortiProxy appliances. Include VPN concentrators and remote access gateways.
- Timeframe: 90-day lookback from hunt initiation (recommended: 2026-06-01 through present). The CHAOS claim against Radia Inc. occurred July 16, 2026; the Women's Center for Radiology incident was discovered around April 28, 2026; the Boston Scientific incident was detected August 25, 2026.
- Priority Systems: PACS servers, Radiology Information Systems (RIS), DICOM storage nodes, imaging workstations, domain controllers serving radiology networks, Fortinet FortiOS/FortiProxy devices (internet-facing), VPN concentrators, EHR systems with imaging integrations, medical device management servers, and any systems with direct access to imaging data stores.
MITRE ATT&CK Techniques
T1190: Exploit Public-Facing Application (Initial Access) [P1]
Gunra actors exploit CVE-2024-55591 and CVE-2025-24472 in internet-facing Fortinet FortiOS and FortiProxy devices to gain initial access. Qilin affiliates exploit Citrix, RDP, and VPN appliances. Exploited vulnerabilities were the top technical cause of healthcare ransomware in 2025, accounting for 33% of incidents.
Splunk SPL:
index=firewall-pan sourcetype="pan:threat" (threat_name="*CVE-2024-55591*" OR threat_name="*CVE-2025-24472*" OR threat_name="*FortiOS*") | stats count by src_ip dest_ip threat_name action | sort -count
Elastic KQL:
event.category:"intrusion_detection" AND (threat.name:*CVE-2024-55591* OR threat.name:*CVE-2025-24472* OR message:*FortiOS* OR message:*FortiProxy*)
Sigma Rule:
title: Exploitation Attempt Against Fortinet FortiOS CVE-2024-55591 or CVE-2025-24472
status: experimental
author: RedSheepSec
date: 2026/09/02
description: Detects potential exploitation attempts targeting CVE-2024-55591 or CVE-2025-24472 in Fortinet FortiOS/FortiProxy devices, as used by Gunra ransomware actors for initial access into healthcare networks.
logsource:
category: firewall
detection:
selection_cve:
threat_name|contains:
- 'CVE-2024-55591'
- 'CVE-2025-24472'
selection_path:
url|contains:
- '/api/v2/cmdb/'
- '/api/v2/monitor/'
http_method: 'PUT'
condition: selection_cve or selection_path
falsepositives:
- Legitimate Fortinet API management traffic from authorized administrators
level: critical
tags:
- attack.initial_access
- attack.t1190
- cve.2024.55591
- cve.2025.24472
Tune by whitelisting known Fortinet management source IPs. Correlate with anomalous admin account creation on FortiOS devices immediately following suspected exploitation. Check Fortinet PSIRT advisory FG-IR-24-535 for specific exploit signatures.
T1566.001: Phishing: Spearphishing Attachment (Initial Access) [P2]
CHAOS, Medusa, and Qilin use spearphishing with malicious attachments as a primary initial access vector. Healthcare organizations are targeted with lures themed around medical billing, insurance claims, and radiology reports.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 (ParentImage="*\\OUTLOOK.EXE" OR ParentImage="*\\WINWORD.EXE" OR ParentImage="*\\EXCEL.EXE") (Image="*\\cmd.exe" OR Image="*\\powershell.exe" OR Image="*\\wscript.exe" OR Image="*\\cscript.exe" OR Image="*\\mshta.exe" OR Image="*\\certutil.exe" OR Image="*\\rundll32.exe") | stats count by Computer ParentImage Image CommandLine User | sort -count
Elastic KQL:
process.parent.name:(OUTLOOK.EXE OR WINWORD.EXE OR EXCEL.EXE) AND process.name:(cmd.exe OR powershell.exe OR wscript.exe OR cscript.exe OR mshta.exe OR certutil.exe OR rundll32.exe)
Sigma Rule:
title: Suspicious Process Spawned by Office Application - Potential Spearphishing
status: experimental
author: RedSheepSec
date: 2026/09/02
description: Detects Office applications spawning suspicious child processes, indicative of spearphishing attachment execution as used by CHAOS, Medusa, and Qilin ransomware groups.
logsource:
product: windows
category: process_creation
detection:
selection_parent:
ParentImage|endswith:
- '\OUTLOOK.EXE'
- '\WINWORD.EXE'
- '\EXCEL.EXE'
- '\POWERPNT.EXE'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\certutil.exe'
- '\rundll32.exe'
condition: selection_parent and selection_child
falsepositives:
- Legitimate Office add-ins or macros
- Administrative scripts triggered from Outlook rules
level: high
tags:
- attack.initial_access
- attack.t1566.001
High false positive potential in environments with heavy macro usage. Baseline legitimate Office-spawned processes and exclude known-good command lines. Focus on workstations belonging to radiology, billing, and administrative staff who handle external communications.
T1078: Valid Accounts (Initial Access) [P2]
CHAOS and Qilin affiliates use brokered credentials and compromised accounts from infostealer malware for initial access. Qilin specifically leverages credentials harvested by infostealer malware to authenticate to VPNs and remote access services.
Splunk SPL:
index=winevent sourcetype="XmlWinEventLog:Security" EventCode=4624 Logon_Type=10 | stats count dc(src_ip) as unique_sources values(src_ip) as source_ips by TargetUserName | where unique_sources > 3 | sort -unique_sources
Elastic KQL:
event.code:"4624" AND winlog.event_data.LogonType:"10" | stats count by winlog.event_data.TargetUserName, source.ip
Sigma Rule:
title: Multiple Source IPs for Single RDP Account - Potential Credential Abuse
status: experimental
author: RedSheepSec
date: 2026/09/02
description: Detects a single account authenticating via RDP from multiple distinct source IPs, which may indicate use of compromised or brokered credentials as observed in CHAOS and Qilin operations.
logsource:
product: windows
service: security
detection:
selection:
EventID: 4624
LogonType: 10
condition: selection
# Aggregation: count distinct SourceNetworkAddress per TargetUserName > 3 within 24h
falsepositives:
- IT administrators using multiple jump boxes
- Shared service accounts
level: medium
tags:
- attack.initial_access
- attack.t1078
Requires post-processing aggregation in SIEM. Tune threshold based on environment. Cross-reference with VPN authentication logs for impossible travel detection. Focus on service accounts and accounts with elevated privileges to PACS/RIS systems.
T1059.001: PowerShell (Execution) [P2]
Medusa and other healthcare-targeting ransomware operators use obfuscated PowerShell for execution, reconnaissance, and lateral movement. PowerShell is a core component of living-off-the-land intrusion chains in healthcare environments.
Splunk SPL:
index=powershell sourcetype="XmlWinEventLog" EventCode=4104 (ScriptBlockText="*-EncodedCommand*" OR ScriptBlockText="*[Convert]::FromBase64String*" OR ScriptBlockText="*Invoke-Expression*" OR ScriptBlockText="*IEX*" OR ScriptBlockText="*Net.WebClient*" OR ScriptBlockText="*DownloadString*" OR ScriptBlockText="*DownloadFile*" OR ScriptBlockText="*Invoke-Mimikatz*" OR ScriptBlockText="*-enc *") | stats count by Computer ScriptBlockText | sort -count
Elastic KQL:
event.code:"4104" AND powershell.file.script_block_text:(*EncodedCommand* OR *FromBase64String* OR *Invoke-Expression* OR *IEX* OR *Net.WebClient* OR *DownloadString* OR *DownloadFile* OR *Invoke-Mimikatz*)
Sigma Rule:
title: Suspicious PowerShell Execution - Obfuscation and Download Cradles
status: experimental
author: RedSheepSec
date: 2026/09/02
description: Detects PowerShell usage patterns consistent with ransomware operator tradecraft including encoded commands, download cradles, and credential dumping tools as documented in Medusa and healthcare intrusion chains.
logsource:
product: windows
category: ps_script
detection:
selection_encoded:
ScriptBlockText|contains:
- '-EncodedCommand'
- '-enc '
- '[Convert]::FromBase64String'
selection_download:
ScriptBlockText|contains:
- 'Net.WebClient'
- 'DownloadString'
- 'DownloadFile'
- 'Invoke-WebRequest'
- 'Start-BitsTransfer'
selection_exec:
ScriptBlockText|contains:
- 'Invoke-Expression'
- 'IEX('
- 'IEX ('
condition: selection_encoded or selection_download or selection_exec
falsepositives:
- Legitimate SCCM or management scripts using encoded commands
- Software deployment tools
level: high
tags:
- attack.execution
- attack.t1059.001
Baseline PowerShell usage on PACS servers and imaging workstations. These systems should have minimal PowerShell activity; any encoded command execution on a PACS server or DICOM workstation is highly suspicious. Consider implementing Constrained Language Mode on imaging systems.
T1059.003: Windows Command Shell (Execution) [P1]
Ransomware operators use cmd.exe for living-off-the-land execution including service manipulation, shadow copy deletion, and reconnaissance. This is a core technique in healthcare ransomware intrusion chains.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 Image="*\\cmd.exe" (CommandLine="*vssadmin*delete*" OR CommandLine="*wmic*shadowcopy*" OR CommandLine="*bcdedit*recoveryenabled*" OR CommandLine="*wbadmin*delete*" OR CommandLine="*net stop*" OR CommandLine="*sc stop*" OR CommandLine="*taskkill*") | stats count by Computer ParentImage CommandLine User | sort -count
Elastic KQL:
process.name:"cmd.exe" AND process.command_line:(*vssadmin*delete* OR *wmic*shadowcopy* OR *bcdedit*recoveryenabled* OR *wbadmin*delete* OR *"net stop"* OR *"sc stop"* OR *taskkill*)
Sigma Rule:
title: Suspicious CMD Execution - Pre-Encryption Activity
status: experimental
author: RedSheepSec
date: 2026/09/02
description: Detects cmd.exe commands associated with ransomware pre-encryption activity including shadow copy deletion, recovery disabling, and service stopping.
logsource:
product: windows
category: process_creation
detection:
selection_image:
Image|endswith: '\cmd.exe'
selection_commands:
CommandLine|contains:
- 'vssadmin delete shadows'
- 'wmic shadowcopy delete'
- 'bcdedit /set {default} recoveryenabled no'
- 'wbadmin delete catalog'
- 'wbadmin delete systemstatebackup'
condition: selection_image and selection_commands
falsepositives:
- Legitimate backup administration tasks
level: critical
tags:
- attack.execution
- attack.t1059.003
- attack.t1490
Shadow copy deletion commands on any system, especially PACS servers or imaging workstations, should trigger immediate investigation. Correlate with service stop events and file encryption activity.
T1021.001: Remote Services: RDP (Lateral Movement) [P2]
Healthcare ransomware operators consistently use RDP for lateral movement across hospital networks. Qilin affiliates specifically exploit exposed RDP services, and RDP is a primary lateral movement mechanism documented in healthcare intrusion chains.
Splunk SPL:
index=winevent sourcetype="XmlWinEventLog:Security" EventCode=4624 Logon_Type=10 | bin _time span=1h | stats dc(TargetUserName) as unique_users dc(Computer) as unique_targets by src_ip _time | where unique_targets > 5 | sort -unique_targets
Elastic KQL:
event.code:"4624" AND winlog.event_data.LogonType:"10" AND NOT source.ip:("127.0.0.1" OR "::1")
Sigma Rule:
title: Lateral Movement via RDP from Unexpected Internal Source
status: experimental
author: RedSheepSec
date: 2026/09/02
description: Detects RDP logon events from internal sources that may indicate lateral movement by ransomware operators. Focus on non-admin workstations initiating RDP to servers, particularly PACS, RIS, or imaging infrastructure.
logsource:
product: windows
service: security
detection:
selection:
EventID: 4624
LogonType: 10
filter_known_admin:
SourceNetworkAddress|startswith:
- '10.0.0.'
condition: selection and not filter_known_admin
falsepositives:
- Legitimate remote administration
- IT helpdesk support sessions
level: medium
tags:
- attack.lateral_movement
- attack.t1021.001
The filter_known_admin section must be customized to match your environment's admin jump box subnets. Focus hunting on RDP sessions originating from clinical workstations or non-IT endpoints reaching PACS/RIS servers. Any RDP from a medical device subnet to a server is suspicious.
T1003.001: OS Credential Dumping: LSASS Memory (Credential Access) [P1]
Qilin and other ransomware affiliates harvest credentials by dumping LSASS process memory during lateral movement through healthcare networks. This enables privilege escalation and broader network compromise.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=10 TargetImage="*\\lsass.exe" (GrantedAccess="0x1010" OR GrantedAccess="0x1038" OR GrantedAccess="0x1F0FFF" OR GrantedAccess="0x1F1FFF" OR GrantedAccess="0x143A") NOT SourceImage="*\\csrss.exe" NOT SourceImage="*\\MsMpEng.exe" NOT SourceImage="*\\svchost.exe" | stats count by Computer SourceImage GrantedAccess User | sort -count
Elastic KQL:
event.code:"10" AND winlog.event_data.TargetImage:*lsass.exe AND winlog.event_data.GrantedAccess:("0x1010" OR "0x1038" OR "0x1F0FFF" OR "0x1F1FFF" OR "0x143A") AND NOT winlog.event_data.SourceImage:(*csrss.exe OR *MsMpEng.exe OR *svchost.exe)
Sigma Rule:
title: LSASS Memory Access - Potential Credential Dumping
status: experimental
author: RedSheepSec
date: 2026/09/02
description: Detects suspicious access to LSASS process memory with access rights commonly used by credential dumping tools such as Mimikatz, as documented in Qilin ransomware operations.
logsource:
product: windows
category: sysmon
detection:
selection:
EventID: 10
TargetImage|endswith: '\lsass.exe'
GrantedAccess:
- '0x1010'
- '0x1038'
- '0x1F0FFF'
- '0x1F1FFF'
- '0x143A'
filter:
SourceImage|endswith:
- '\csrss.exe'
- '\MsMpEng.exe'
- '\svchost.exe'
- '\WerFault.exe'
condition: selection and not filter
falsepositives:
- EDR and AV products accessing LSASS
- Windows Error Reporting
level: critical
tags:
- attack.credential_access
- attack.t1003.001
Any LSASS access from non-system processes on PACS servers, imaging workstations, or domain controllers warrants immediate escalation. Enable Credential Guard on all eligible Windows systems to mitigate. Whitelist your EDR agent's process path.
T1548.002: Abuse Elevation Control Mechanism: Bypass UAC (Privilege Escalation) [P2]
Qilin ransomware uses UAC bypass techniques for privilege escalation on compromised Windows systems.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 IntegrityLevel=High (ParentImage="*\\dllhost.exe" OR ParentImage="*\\eventvwr.exe" OR ParentImage="*\\fodhelper.exe" OR ParentImage="*\\computerdefaults.exe" OR ParentImage="*\\sdclt.exe") (Image="*\\cmd.exe" OR Image="*\\powershell.exe") | stats count by Computer ParentImage Image CommandLine User | sort -count
Elastic KQL:
process.parent.name:(dllhost.exe OR eventvwr.exe OR fodhelper.exe OR computerdefaults.exe OR sdclt.exe) AND process.name:(cmd.exe OR powershell.exe) AND process.Ext.token.integrity_level_name:"high"
Sigma Rule:
title: UAC Bypass via Auto-Elevating Binary - Qilin Ransomware TTP
status: experimental
author: RedSheepSec
date: 2026/09/02
description: Detects UAC bypass using auto-elevating Windows binaries as documented in Qilin ransomware privilege escalation techniques.
logsource:
product: windows
category: process_creation
detection:
selection_parent:
ParentImage|endswith:
- '\eventvwr.exe'
- '\fodhelper.exe'
- '\computerdefaults.exe'
- '\sdclt.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\mshta.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare legitimate use cases
level: high
tags:
- attack.privilege_escalation
- attack.t1548.002
UAC bypass is a reliable indicator of active intrusion. On imaging workstations and PACS servers, these parent-child process relationships should essentially never occur legitimately.
T1486: Data Encrypted for Impact (Impact) [P1]
Core ransomware function across CHAOS, Medusa, Gunra, and Qilin. Although encryption rates have dropped to 34% in healthcare according to Sophos 2025 data, encryption remains the primary impact mechanism when deployed. CHAOS supports configurable encryption and optional partial-file targeting for stealth.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=11 (TargetFilename="*.encrypted" OR TargetFilename="*.locked" OR TargetFilename="*.chaos" OR TargetFilename="*.medusa" OR TargetFilename="*.qilin" OR TargetFilename="*.gunra" OR TargetFilename="*HOW_TO_DECRYPT*" OR TargetFilename="*RECOVER_FILES*" OR TargetFilename="*RESTORE_YOUR_FILES*" OR TargetFilename="*DECRYPT_INSTRUCTION*" OR TargetFilename="*README_FOR_DECRYPT*" OR TargetFilename="*!!!READ_ME*") | stats count by Computer TargetFilename Image User | sort -count
Elastic KQL:
event.code:"11" AND file.path:(*encrypted OR *locked OR *chaos OR *medusa OR *qilin OR *gunra OR *HOW_TO_DECRYPT* OR *RECOVER_FILES* OR *RESTORE_YOUR_FILES* OR *DECRYPT_INSTRUCTION* OR *README_FOR_DECRYPT*)
Sigma Rule:
title: Ransom Note File Creation in Healthcare Environment
status: experimental
author: RedSheepSec
date: 2026/09/02
description: Detects creation of files matching known ransom note patterns used by CHAOS, Medusa, Gunra, Qilin, and other ransomware groups targeting healthcare. Adapted from the source report detection guidance.
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|contains:
- 'HOW_TO_DECRYPT'
- 'RECOVER_FILES'
- 'RESTORE_YOUR_FILES'
- 'DECRYPT_INSTRUCTION'
- 'README_FOR_DECRYPT'
- '!!!READ_ME'
condition: selection
falsepositives:
- Security testing or red team exercises
level: critical
tags:
- attack.impact
- attack.t1486
This is a late-stage detection; if ransom notes are being created, encryption is likely underway. On PACS servers, any ransom note creation is a critical incident. Correlate with mass file rename events and service stop activity. Note that clinical imaging systems can legitimately produce file-operation bursts that may trigger false positives for mass file-rename rules; establish DICOM I/O baselines first.
T1490: Inhibit System Recovery (Impact) [P1]
Ransomware groups including Qilin delete Volume Shadow Copies and disable recovery options prior to encryption to prevent victims from restoring data without paying the ransom.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 (CommandLine="*vssadmin*delete*shadow*" OR CommandLine="*wmic*shadowcopy*delete*" OR CommandLine="*bcdedit*/set*recoveryenabled*no*" OR CommandLine="*wbadmin*delete*catalog*" OR CommandLine="*wbadmin*delete*systemstatebackup*") | stats count by Computer Image CommandLine ParentImage User _time | sort -_time
Elastic KQL:
process.command_line:(*vssadmin*delete*shadow* OR *wmic*shadowcopy*delete* OR *bcdedit*recoveryenabled*no* OR *wbadmin*delete*catalog*)
Sigma Rule:
title: Shadow Copy Deletion and Recovery Inhibition
status: experimental
author: RedSheepSec
date: 2026/09/02
description: Detects commands used to delete shadow copies and disable system recovery, a critical pre-encryption step in ransomware attacks including Qilin and other RaaS variants targeting healthcare.
logsource:
product: windows
category: process_creation
detection:
selection_vss:
CommandLine|contains|all:
- 'vssadmin'
- 'delete'
- 'shadows'
selection_wmic:
CommandLine|contains|all:
- 'wmic'
- 'shadowcopy'
- 'delete'
selection_bcdedit:
CommandLine|contains|all:
- 'bcdedit'
- 'recoveryenabled'
- 'no'
selection_wbadmin:
CommandLine|contains|all:
- 'wbadmin'
- 'delete'
condition: selection_vss or selection_wmic or selection_bcdedit or selection_wbadmin
falsepositives:
- Legitimate backup rotation scripts (rare to use vssadmin delete)
level: critical
tags:
- attack.impact
- attack.t1490
Shadow copy deletion is one of the strongest pre-encryption indicators. Immediate containment actions should be initiated if detected. On PACS or RIS servers, this should never occur during normal operations.
T1489: Service Stop (Impact) [P1]
Ransomware groups stop security services, backup agents, and database services prior to encryption to maximize impact and prevent interference. This is documented across Qilin and other RaaS operations.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=1 (CommandLine="*net stop*" OR CommandLine="*sc stop*" OR CommandLine="*taskkill /f /im*") (CommandLine="*sql*" OR CommandLine="*backup*" OR CommandLine="*veeam*" OR CommandLine="*sophos*" OR CommandLine="*symantec*" OR CommandLine="*malware*" OR CommandLine="*exchange*" OR CommandLine="*oracle*") | stats count by Computer CommandLine ParentImage User _time | sort -_time
Elastic KQL:
process.command_line:(*"net stop"* OR *"sc stop"* OR *"taskkill /f"*) AND process.command_line:(*sql* OR *backup* OR *veeam* OR *sophos* OR *symantec* OR *exchange* OR *oracle*)
Sigma Rule:
title: Mass Service Stop - Pre-Encryption Ransomware Activity
status: experimental
author: RedSheepSec
date: 2026/09/02
description: Detects stopping of security, backup, and database services commonly targeted by ransomware operators before encryption.
logsource:
product: windows
category: process_creation
detection:
selection_cmd:
CommandLine|contains:
- 'net stop'
- 'sc stop'
selection_services:
CommandLine|contains:
- 'sql'
- 'backup'
- 'veeam'
- 'sophos'
- 'symantec'
- 'exchange'
- 'oracle'
- 'mysql'
- 'tomcat'
condition: selection_cmd and selection_services
falsepositives:
- Legitimate maintenance windows
- Patch management processes
level: high
tags:
- attack.impact
- attack.t1489
Multiple service stop commands in quick succession is a strong ransomware indicator. Correlate with shadow copy deletion and ransom note creation. Schedule maintenance windows in your SIEM to suppress during planned outages.
T1567.002: Exfiltration Over Web Service: Exfiltration to Cloud Storage (Exfiltration) [P2]
Double-extortion ransomware groups including CHAOS exfiltrate data to cloud storage before encryption or extortion demands. The CHAOS group claimed 655 GB exfiltration from Radia Inc. Extortion-only attacks (data stolen but not encrypted) tripled to 12% of healthcare cases, making exfiltration detection critical.
Splunk SPL:
index=corelight sourcetype="corelight_http" (host_header="*mega.nz*" OR host_header="*transfer.sh*" OR host_header="*file.io*" OR host_header="*send.firefox.com*" OR host_header="*gofile.io*" OR host_header="*anonfiles.com*" OR host_header="*dropmefiles.com*" OR host_header="*temp.sh*") | stats sum(request_body_len) as bytes_out count by id_orig_h host_header | eval MB_out=round(bytes_out/1048576,2) | where MB_out > 100 | sort -MB_out
Elastic KQL:
destination.domain:(*mega.nz OR *transfer.sh OR *file.io OR *gofile.io OR *anonfiles.com OR *dropmefiles.com OR *temp.sh) AND network.bytes > 104857600
Sigma Rule:
title: Large Data Upload to Cloud File Sharing Service - Potential Exfiltration
status: experimental
author: RedSheepSec
date: 2026/09/02
description: Detects large uploads to known cloud file sharing services, consistent with double-extortion ransomware data theft as seen in CHAOS operations against healthcare radiology targets.
logsource:
category: proxy
detection:
selection:
c-uri|contains:
- 'mega.nz'
- 'transfer.sh'
- 'file.io'
- 'gofile.io'
- 'anonfiles.com'
- 'dropmefiles.com'
- 'temp.sh'
condition: selection
falsepositives:
- Legitimate use of cloud file sharing services
- Large file transfers by authorized users
level: high
tags:
- attack.exfiltration
- attack.t1567.002
Supplement with bulk file access detection on PACS servers and file shares. Monitor for staging of ZIP, 7z, and RAR archives in unusual directories (e.g., C:\ProgramData, C:\Users\Public, temp directories). Focus on outbound transfers exceeding 100 MB to uncommon destinations.
T1566.002: Phishing: Spearphishing Link (Initial Access) [P3]
Medusa operators use spearphishing links for credential theft, directing victims to fake authentication portals to harvest credentials for subsequent access.
Splunk SPL:
index=corelight sourcetype="corelight_http" method=POST (uri="*login*" OR uri="*signin*" OR uri="*auth*") status_code=200 NOT host_header IN ("login.microsoftonline.com", "accounts.google.com", "auth.mil") | stats count by id_orig_h host_header uri | where count > 0 | sort -count
Elastic KQL:
http.request.method:"POST" AND url.path:(*login* OR *signin* OR *auth*) AND NOT destination.domain:("login.microsoftonline.com" OR "accounts.google.com" OR "auth.mil")
This is a broad anomaly hunt for credential submission to unfamiliar domains. Requires tuning against legitimate authentication targets. Cross-reference with email gateway logs for inbound links directing users to these domains.
YARA Rules
ransom_note_healthcare_generic: Detects common ransom note file content patterns associated with ransomware groups targeting healthcare, including file name patterns and instructional text commonly found in CHAOS, Medusa, Qilin, and Gunra ransom notes.
rule ransom_note_healthcare_generic
{
meta:
author = "RedSheepSec"
description = "Detects common ransom note content patterns from ransomware groups targeting healthcare and radiology"
date = "2026-09-02"
reference = "PEAK Hunt: Healthcare Radiology Ransomware"
strings:
$note1 = "HOW_TO_DECRYPT" ascii wide nocase
$note2 = "RECOVER_FILES" ascii wide nocase
$note3 = "RESTORE_YOUR_FILES" ascii wide nocase
$note4 = "DECRYPT_INSTRUCTION" ascii wide nocase
$note5 = "README_FOR_DECRYPT" ascii wide nocase
$note6 = "!!!READ_ME" ascii wide nocase
$tor1 = ".onion" ascii wide
$btc1 = "bitcoin" ascii wide nocase
$btc2 = /[13][a-km-zA-HJ-NP-Z1-9]{25,34}/ ascii
$contact1 = "contact us" ascii wide nocase
$contact2 = "your files have been encrypted" ascii wide nocase
$contact3 = "your data has been stolen" ascii wide nocase
condition:
(any of ($note*)) or (any of ($contact*) and any of ($tor1, $btc1, $btc2))
}
staging_archive_suspicious_location: Detects archive files (ZIP, 7z, RAR) created in suspicious staging directories commonly used by ransomware operators for data staging before exfiltration, relevant to extortion-only attack patterns.
rule staging_archive_suspicious_location
{
meta:
author = "RedSheepSec"
description = "Detects archive file headers in suspicious staging locations used for data exfiltration by double-extortion ransomware operators"
date = "2026-09-02"
reference = "PEAK Hunt: Healthcare Radiology Ransomware - Extortion-Only Detection"
strings:
$zip_header = { 50 4B 03 04 }
$rar_header = { 52 61 72 21 1A 07 }
$sevenzip_header = { 37 7A BC AF 27 1C }
$path1 = "\\ProgramData\\" ascii wide nocase
$path2 = "\\Users\\Public\\" ascii wide nocase
$path3 = "\\Temp\\" ascii wide nocase
$path4 = "\\Windows\\Temp\\" ascii wide nocase
condition:
(any of ($zip_header, $rar_header, $sevenzip_header)) and (any of ($path*))
}
Suricata Rules
SID 2026001: Detects outbound connections to known file sharing services commonly used for ransomware data exfiltration in double-extortion operations
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"REDSHEEPSEC Potential Ransomware Exfiltration to Cloud File Sharing"; flow:established,to_server; http.host; content:"mega.nz"; sid:2026001; rev:1; classtype:policy-violation; metadata:created_at 2026_09_02, updated_at 2026_09_02;)
SID 2026002: Detects outbound connections to transfer.sh, a file sharing service abused by ransomware operators for data exfiltration
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"REDSHEEPSEC Potential Ransomware Exfiltration to transfer.sh"; flow:established,to_server; http.host; content:"transfer.sh"; sid:2026002; rev:1; classtype:policy-violation; metadata:created_at 2026_09_02, updated_at 2026_09_02;)
SID 2026003: Detects outbound connections to gofile.io, a file sharing service used for data exfiltration by ransomware operators
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"REDSHEEPSEC Potential Ransomware Exfiltration to gofile.io"; flow:established,to_server; http.host; content:"gofile.io"; sid:2026003; rev:1; classtype:policy-violation; metadata:created_at 2026_09_02, updated_at 2026_09_02;)
SID 2026004: Detects large outbound data transfer that may indicate bulk data exfiltration consistent with double-extortion ransomware activity
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"REDSHEEPSEC Large Outbound Data Transfer - Potential Exfiltration"; flow:established,to_server; dsize:>10000; threshold:type both,track by_src,count 1000,seconds 300; sid:2026004; rev:1; classtype:policy-violation; metadata:created_at 2026_09_02, updated_at 2026_09_02;)
Data Source Requirements
| Source | Required For | Notes |
|---|---|---|
| Sysmon (Windows) | T1059.001, T1059.003, T1003.001, T1548.002, T1486, T1490, T1489, T1566.001, T1021.001 | Requires Sysmon EventIDs 1 (Process Creation), 3 (Network Connection), 10 (Process Access for LSASS), 11 (File Create), 13 (Registry Value Set). Verify Sysmon is deployed on PACS servers, imaging workstations, RIS systems, and domain controllers. Index: sysmon, sourcetype: XmlWinEventLog. |
| Windows Security Event Log | T1078, T1021.001 | Requires EventID 4624 (Logon), 4625 (Failed Logon), 4648 (Explicit Credentials), 4688 (Process Creation with command line auditing). Index: winevent, sourcetype: XmlWinEventLog:Security. |
| PowerShell Script Block Logging | T1059.001 | Requires PowerShell ScriptBlock Logging (EventID 4104) and Module Logging enabled via GPO. Index: powershell, sourcetype: XmlWinEventLog. |
| Corelight/Zeek Network Metadata | T1567.002, T1566.002, T1190 | Requires corelight_http, corelight_ssl, corelight_conn, corelight_dns sourcetypes for network-based exfiltration and exploitation detection. Index: corelight. |
| Palo Alto Firewall Logs | T1190, T1567.002 | Requires pan:threat for IPS/IDS signatures matching CVE exploitation and pan:traffic:aggregated for large data transfer detection. Index: firewall-pan. |
| CrowdStrike EDR | T1003.001, T1486, T1548.002 | CrowdStrike detection events for credential access, ransomware behavior, and privilege escalation. Index: crowdstrike. |
| Fortinet FortiOS Syslogs | T1190 | FortiOS system and security event logs for detecting CVE-2024-55591 and CVE-2025-24472 exploitation. Check if these are ingested into index=firewall or index=net-device. May require custom onboarding if not currently collected. |
Recommendations
- Immediately audit all internet-facing Fortinet FortiOS and FortiProxy appliances for CVE-2024-55591 (CVSS 9.8) and CVE-2025-24472. Apply patches per Fortinet PSIRT advisory FG-IR-24-535. Gunra actively exploits both vulnerabilities for initial access into healthcare networks.
- Deploy all Sigma rules and Splunk/Elastic queries from this hunt report across production SIEM instances, prioritizing P1 detections (LSASS access, shadow copy deletion, ransom note creation, service stopping, Fortinet exploitation) for immediate alerting.
- Implement monitoring for bulk file access and large outbound data transfers from PACS servers, RIS, and EHR-connected imaging shares. Configure alerts for archive file creation (ZIP, 7z, RAR) in staging directories (C:\ProgramData, C:\Users\Public, temp paths). Extortion-only attacks will not trigger encryption-based detection rules.
- Enforce phishing-resistant MFA (FIDO2/WebAuthn) on all VPN, RDP, and remote access accounts. Prioritize accounts with access to imaging infrastructure, PACS, and RIS systems. Review for any accounts using password-only authentication.
- Verify Sysmon deployment coverage includes PACS servers, imaging workstations, RIS systems, and domain controllers serving radiology network segments. Confirm EventID 10 (Process Access) logging is enabled for LSASS monitoring.
- Baseline normal DICOM file I/O patterns on PACS servers to establish reliable detection thresholds. Clinical imaging systems legitimately produce file-operation bursts that can trigger false positives for mass file-rename or mass file-access detection rules.
- Review and apply the ACR/SIIM joint cybersecurity white paper (2025, DOI: 10.1007/s10278-025-01621-4) for imaging-specific hardening, incident response planning, and vendor management guidance.
- Confirm backup integrity and test offline restoration procedures specifically for PACS and RIS systems. Ensure backups are immutable or air-gapped to prevent ransomware from encrypting backup stores.
- Block or alert on unauthorized cloud file sharing services (mega.nz, transfer.sh, gofile.io, anonfiles.com, dropmefiles.com) at the network perimeter via Palo Alto URL filtering or proxy controls.
- Enable Credential Guard on all eligible Windows systems, particularly domain controllers and PACS/RIS servers, to mitigate LSASS credential dumping techniques used by Qilin and other ransomware operators.
- Conduct a supply chain risk assessment for vendor-managed imaging equipment, cloud-hosted AI inference services, and third-party PACS hosting. The Boston Scientific incident (August 2026) demonstrates downstream supply chain disruption risk.
Sources
- Radiology practice agrees to $3.3M settlement in class-action lawsuit over cyberattack
- The State of Ransomware 2026 - BlackFog
- Radia 2026 Data Breach - ClaimDepot
- Radia Class Action Investigation
- CHAOS Ransomware Group Strikes Radia Inc.
- CHAOS Ransomware Group Profile - RansomLook
- Radiology Ransomware Cyberattack - Healthcare in Europe
- ACR/SIIM Joint Cybersecurity White Paper (2025)
- Qilin Ransomware Analysis Impact and Defense 2025 - BlackFog
- Qilin (Agenda) - MITRE ATT&CK Software S1242
- Qilin Ransomware Attack Analysis - Rescana
- Qilin Ransomware Explained: Threats, Risks, Defenses - Qualys
- Medusa Ransomware 2026 - CyberFence Platform
- Ransomware State of Healthcare 2025 - HIT Consultant
- Sophos State of Ransomware in Healthcare 2025 - CXO Today
- Radiology vs Ransomware: How to Defend Imaging Departments - Quomi
- Attorney General James Secures $450,000 from Medical Company - NY AG
- Deep Dive Into the Boston Scientific Cyberattack - ShieldWorkz
- CISA Warns Healthcare Should Prepare for Disruptive Cyberattacks - Paubox
- Ransomware Breaches at Five US Healthcare Providers: Detection and Hardening Guide - Security Arsenal
- Ransomware in Healthcare Attack Timeline - CybelAngel